← Vulnerability feed

Vulnerability record · CVE-2022-36098 · published 8 September 2022

CVE-2022-36098: XWiki Mentions UI stored XSS via mention and macro fields

Xwiki · Xwiki

XWiki Platform Mentions UI allows JavaScript or Groovy scripts to be stored in a mention, macro anchor, or reference field. The stored code executes for anyone who visits the page containing the mention, making it a persistent cross-site scripting flaw. It affects versions from 12.5-rc-1 before 13.10.6 and 14.4, and is patched in 14.4 and 13.10.6.

9.0 CVSS 3.1 Critical EPSS 72% · top 0.6% CWE-79 · Cross-site scripting
9.0CVSS 3.1 base score
72%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

XWiki Platform Mentions UI is a user interface for mentioning users in wiki content for XWiki Platform, a generic wiki platform. Starting in version 12.5-rc-1 and prior to versions 13.10.6 and 14.4, it's possible to store Javascript or groovy scripts in a mention, macro anchor, or reference field. The stored code is executed by anyone visiting the page with the mention. This issue has been patched on XWiki 14.4 and 13.10.6. As a workaround, one may update `XWiki.Mentions.MentionsMacro` and edit the `Macro code` field of the `XWiki.WikiMacroClass` XObject.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 3.1 base score is 9.0 (critical) with high confidentiality, integrity, and availability impact, and EPSS is 0.71043 at the 99.37th percentile.

What it is

XWiki Platform Mentions UI allows JavaScript or Groovy scripts to be stored in a mention, macro anchor, or reference field. The stored code executes for anyone who visits the page containing the mention, making it a persistent cross-site scripting flaw. It affects versions from 12.5-rc-1 before 13.10.6 and 14.4, and is patched in 14.4 and 13.10.6.

Impact

An attacker with a low-privileged account can plant script that runs in the browser of every user viewing the affected page, enabling session theft, actions as the victim, or further compromise of the wiki. Because the scope is changed, the injected code can affect resources beyond the vulnerable component.

Attack surface

Reached over the network through wiki content that includes a mention, macro anchor, or reference field; the attacker needs a low-privileged authenticated account to store the payload, and a victim must visit the page for execution.

Exploitation

Not listed in CISA KEV, but EPSS is very high at 0.71043 (99.37th percentile) and the advisory and Jira references are tagged Exploit, indicating public exploit information exists.

What to do

  • Upgrade XWiki Platform to 14.4 or 13.10.6 or later.
  • If immediate upgrade is not possible, apply the documented workaround by updating XWiki.Mentions.MentionsMacro and editing the Macro code field of the XWiki.WikiMacroClass XObject.
  • Restrict who can create or edit wiki content containing mentions, macro anchors, and reference fields.
  • Review and sanitize existing mentions and macro fields for stored script content.
  • Monitor vendor advisories for further guidance on this issue.

Detection

  • Search wiki content and page history for mention, macro anchor, or reference fields containing script tags or Groovy code.
  • Alert on edits to XWiki.Mentions.MentionsMacro or the XWiki.WikiMacroClass XObject Macro code field.
  • Monitor web logs and application logs for requests to pages with mentions that correlate with unexpected script execution or user session anomalies.
  • Audit accounts with low privileges that create or modify mentions for suspicious payload patterns.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-36098 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-24893XWiki SolrSearch unauthenticated remote code executionXWiki Platform's SolrSearch endpoint evaluates user-supplied search text as Groovy code, allowing arbitrary remote code execution. The flaw is reacha…KEVEPSS 100%analysed9.9CVE-2023-27479Xwiki injection vulnerabilityXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with view righ…EPSS 1.1%9.8CVE-2024-31996Xwiki code injection vulnerabilityXWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, the HTML escaping of esca…EPSS 2.1%9.8CVE-2024-31982Xwiki code injection vulnerabilityXWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's databas…EPSS 35%9.8CVE-2024-21650XWiki user registration RCE via name fieldsXWiki Platform is vulnerable to remote code execution through its guest user registration feature. An attacker can inject malicious payloads into the…EPSS 93%analysed9.8CVE-2023-46731XWiki Platform unescaped URL parameter allows remote code executionXWiki Platform fails to properly escape the section URL parameter used when displaying administration sections, allowing injection of code such as Gr…EPSS 89%analysed9.8CVE-2023-26477XWiki Platform unauthenticated code injection via newThemeName parameterXWiki Platform versions from 6.3-rc-1 and 6.2.4 onward allow injection of arbitrary wiki syntax, including Groovy, Python and Velocity script macros,…EPSS 75%analysed9.8CVE-2022-29161Xwiki broken cryptographic algorithm vulnerabilityXWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The XWiki Crypto API will generate X509 cert…EPSS 0.41%

Source: NIST National Vulnerability Database (record CVE-2022-36098), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.